PT-2021-18641 · Unknown · Network Camera Device

Chunhao Yang

+1

·

Published

2021-04-28

·

Updated

2022-10-25

·

CVE-2021-30167

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Network camera device (affected versions not specified)
Description The issue concerns the manage users profile services of the network camera device, which allows an authenticated remote attacker to modify URL parameters and amend a user's information. This can lead to privilege escalation, enabling the attacker to control the devices.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2021-30167

Affected Products

Network Camera Device